Regulatory Verification

Every requirement, answered with evidence.

We examine your website against every requirement that applies to it and record each one as met or not met, with the evidence and the clause behind it. A public page confirms the report was issued by STRASYS.

  • Not a certificate
  • Not legal advice
  • Point in time
GDPRePrivacyEAA / WCAGKVKKAI ActDSA

Three registers, kept apart on purpose: legal, standard and method.

A report that names only the law describes half of what it measured. Every criterion in this report sits in exactly one register, so you always know which findings could put you in front of a regulator and which could not.

Legal criteria

Law in force

A statute or a directly applicable instrument. A finding here is a requirement that was met or not met, and the consequence exists outside this document.

GDPR, EAA, KVKK
Standard criteria

Published specifications

Specifications from bodies that are not legislatures: schema.org, the IETF, Google, OWASP. Conformance is not compulsory; findings are reported as information.

schema.org, OWASP
Method criteria

The STRASYS checklist

Proprietary checks and commercial judgment about a website, labelled as such so they are never mistaken for a legal requirement.

STRASYS method
Criteria applied

Eight regimes, three regional packs.

The regimes in scope are chosen per engagement from where you operate and whom you serve. Each is cited by article or clause, with the authority, the effective date and the enforcement range on the criteria page of the report.

01GDPR (EU) 2016/67902ePrivacy Directive 2002/58/EC03European Accessibility Act (EU) 2019/88204EN 301 549 / WCAG 2.2 AA05AI Act (EU) 2024/1689, Art. 5006Digital Services Act (EU) 2022/206507KVKK, Law No. 6698 (Türkiye)08ETBIS and E-Commerce Law No. 656309Singapore PDPA 201210EU pack11Türkiye pack12Singapore pack

Packs: EU (GDPR, ePrivacy, EAA, AI Act, DSA), Türkiye (KVKK, ETBIS and 6563), Singapore (PDPA). Accessibility is verified against WCAG 2.2 AA through EN 301 549, the yardstick the European Accessibility Act enforces.

What the report contains

One document, every examination recorded.

The report is self-contained: criteria, requirement records, evidence index, document, sampling and system examinations, and the verification record. Around one hundred pages for a typical site.

Requirement register

Every applicable requirement with its verdict: met, not met, not applicable, outside method or outside scope. No partial verdicts; how badly a requirement is missed travels on the finding class.

Recorded
  • Clause reference for every row
  • Finding class: observation, minor, major
  • Neutral verdicts kept separate

Evidence index

What was fetched, when, from where, and its fingerprint. A finding without evidence is not issued.

Recorded
  • Timestamped retrievals
  • SHA-256 per artefact
  • Source and path recorded

Document examination

Contracts, notices and policies the web surface cannot reach are examined element by element, against the provision each element comes from.

Recorded
  • Document never stored, only its fingerprint
  • Present, deficient or absent per element
  • Provision cited per element

Sampling and systems

Record extracts and system settings the regulation requires, sampled and observed, with the selection method written down.

Recorded
  • Selection method disclosed
  • Observation status per item
  • Access route recorded

Declarations

What the obligated party declares about itself, recorded separately from what was examined, so the two are never confused.

Recorded
  • Declaration kinds enumerated
  • Outcome per declaration
  • Refusals recorded as such

Verification record

A public page, reachable by link or QR code, confirms the report id, the issue date, the issuer and whether the report has been withdrawn.

Recorded
  • No findings on the public page
  • Withdrawal is visible
  • Works without an account
How it is done

Scoped, examined, reviewed, issued.

01

Scope and authorisation

You confirm the site, the regime packs and your written authorisation to examine it. Nothing is fetched before that.

02

Examination

Automatable checks run against the live site; content is read; documents, samples and systems you share are examined element by element.

03

Assessor review

Every verdict is entered by the assessor. AI drafts where it helps; it never decides a requirement.

04

Issue and verify

The report is issued as a numbered revision with a verification page. A later revision supersedes it and says so.

What this report is not

A statement of fact, not a certificate.

The boundaries are printed in the report and on this page, in the same words.

01Not a certificate of conformity; the declaration and the legal responsibility stay with the obligated party02Not an accredited inspection or certification service03Not legal advice; it does not replace counsel in the jurisdictions where you operate04Point in time: it describes the site as observed during the assessment period05Examined and released by a single assessor; no independent review step is claimed
Founder

Built by the person who ran the operation.

20+ years in operations, 15+ in senior leadership, 10 with full P&L as GM and VP. The verification report follows the reporting discipline he worked under for two decades.

About the founder →
20+years in operations
15+countries
10years with full P&L
What it costs

Scoped per site and pack, quoted in writing.

The price depends on the size of the site, the regime packs and whether documents, samples and systems are in scope. You receive a written scope and a written price after one call.

01Requirement by requirement
Regulatory Verification
Written quote
Every applicable requirement recorded as met or not met, with evidence.
  • Criteria page with authority, effective date, enforcement range
  • Evidence index and public verification page
  • Document, sampling and system examinations where in scope
  • Bilingual: English or Turkish
Scoped per site and regime pack
Book a verification call →
02Start here
Digital Audit
$199
150+ points across 16 areas, with a 30+ page report.
  • Infrastructure, security, privacy and consent
  • SEO, structured data, AI visibility
  • Forms, analytics, performance, accessibility
  • One-time, credited toward a build
One-time · 30+ page report
About the audit →
Not sure which one you need?
Write to us with your address and where you operate; we will tell you which report fits.
care@strasysglobal.com
Questions

Answered before you ask.

Is this a certificate?

No. It is a third-party verification report: a statement of what was examined and whether each requirement was met. It is not a certificate of conformity and STRASYS is not an accredited certification or inspection body.

Is it legal advice?

No. The report records facts against published requirements. What to do about a finding in your jurisdiction is a question for your counsel; the report gives them the evidence.

Which laws are covered?

GDPR, the ePrivacy Directive, the European Accessibility Act with EN 301 549 and WCAG 2.2 AA, the AI Act transparency article, the Digital Services Act, KVKK, ETBIS with the Turkish E-Commerce Law, and the Singapore PDPA, selected per engagement as EU, Türkiye and Singapore packs.

How is the site examined?

Automatable checks run against the publicly reachable site during a recorded assessment period; content is read; documents, record extracts and system settings you share are examined and only their fingerprint is kept. No active security testing is performed.

Who does the work?

The founder of STRASYS, as a single assessor. The report says so, and it says that no independent review step is claimed.

How does someone check that a report is genuine?

Every issued report carries a verification link and a QR code. The public page confirms the report id, issue date and issuer, and shows whether the report has been withdrawn. It shows no findings.

Where to start

Start with a product, or with a conversation.

Install a product today, set it up together, scope custom software or start with an audit.

01Software solutions
Software solutions
Six products. One Platform. Custom software.
Management Suite: six products, 30-day trial, list prices.
STRASYS Platform: six disciplines, one layer. In development.
Custom Software & AI: built on your process. Written price.
  • Monthly or annual plans
  • Seat plans from 10 seats
  • iPhone, Android, Windows, web
  • No card, no call, cancel any time
List prices online
See pricing →
02For companies
Set it up with us
Configured together, ready for the first quarter.
Sites, roles, users and data import configured with you after a free 30-minute call.
  • Free 30-minute call first
  • One working session
  • First quarter entered together
  • Written quote before the session
30 min · free call
Book a software call →
03Designed end to end
Custom Software & AI
Built on your own process, by one person, A to Z.
Thirty minutes is usually enough to understand the need. The rest is designed and built by the founder.
  • One scoping call
  • Written scope and price
  • Same standard as the six products
  • Handed over, no retainer
60 min · written scope and price
Scope custom software →
04For your web presence
Digital Audit & Regulatory Verification
Know exactly where your website stands.
A 150+ point audit with a 30+ page report, or a regulatory verification report with evidence for every finding.
  • Digital audit, one-time
  • Verification: met or not met, with evidence
  • Public verification page
  • Not a certificate, not legal advice
30 min · free call
Book an audit call →
None of these fit?

Write to us and we will point you to the right path.

care@strasysglobal.com